TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Crypto hedge fund Three Arrows files for bankruptcy

    July 2, 2022

    There’s a better way to bypass Windows 11 install restrictions

    July 2, 2022

    Biden administration floats new oil leasing plan in Gulf of Mexico

    July 1, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      There’s a better way to bypass Windows 11 install restrictions

      July 2, 2022

      What is the best controller for Xbox consoles?

      July 1, 2022

      The GPU shortage is over

      July 1, 2022

      Google will start auto-deleting abortion clinic visits from user location history

      July 1, 2022

      The government’s going after alleged crypto scammers as market crashes

      July 1, 2022
    • Business
    • Cyber Security

      Tips to bolster cybersecurity, incident response this 4th of July weekend

      July 1, 2022

      Jon Raper named CISO at Costco

      July 1, 2022

      2022 RSAC takeaways: Risk management vs compliance

      July 1, 2022

      3 security lessons we haven’t learned from the Kaseya breach

      July 1, 2022

      Auston Davis named CISO at Versant Health

      June 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»Dridex/Locky Operator Uses New RAT in Recent Campaigns
    Cyber Security

    Dridex/Locky Operator Uses New RAT in Recent Campaigns

    January 13, 2019Updated:January 14, 2019No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Have you been attacked? Digitpol the global investigation firm can help you, visit Digitpol’s website to learn more.


    The threat actor responsible for large Dridex and Locky distribution campaigns in the past has been using a brand new backdoor in attacks over the past couple of months, Proofpoint reports. 

    Tracked by Proofpoint as TA505, the adversary has been distributing a new backdoor named ServHelper since November 2018, and also serving the FlawedGrace malware to its victims. The attacks hit banks, retail businesses, and restaurants. 

    The ServHelper malware, the researchers say, has two variants, one designed to provide remote desktop capabilities to the attackers, and another primarily designed as a downloader. This second variant of the malware was observed serving the FlawedGrace remote access Trojan, Proofpoint’s security researchers report. 

    The first campaign delivering ServHelper was observed on November 9 and featured only thousands of email messages. Mainly targeting financial institutions, the attack used Microsoft Word or Publisher attachments containing malicious macros that would download and execute the malware. 

    A second campaign was observed on November 15, featuring tens of thousands of messages and targeting the retail industry, in addition to financial institutions. The campaign featured Microsoft “.doc”, “.pub”, or “.wiz” attachments that attempted to download the downloader version of ServHelper. 

    A third attack, observed on December 13, targeted retail and financial services customers with Word attachments with embedded malicious macros, PDF attachments with URLs linking to a fake page, and direct URLs to a ServHelper downloader executable. As part of this campaign, the malware also attempted to download and execute the FlawedGrace RAT.

    ServHelper is written in Delphi and appears to be under active development, with new commands and functions being added to it with each new campaign. 

    The backdoor variant of the malware has more features and focuses on setting up reverse SSH tunnels to facilitate access to the compromised host via Remote Desktop Protocol (RDP), which allows the attackers to hijack legitimate user accounts. The downloader variant lacks both the tunneling and hijacking functionality.

    ServHelper uses HTTP protocol on port 443 (HTTPS) and, less frequently, port 80 (HTTP), to communicate with the command and control (C&C) server. 

    The security researchers observed in the malware commands to implement keep-alive functionality, set a reverse SSH tunnel, set a sleep timeout, copy Firefox profile, copy Chrome profiles, kill the SSH tunnel for a particular remote port, get a list of active SSH tunnels, kill all SSH tunnel processes, execute shell command, fetch and run an executable, remove itself from the machine, load DLLs, hijack a user account, and set up an “alerting” mechanism.

    The FlawedGrace RAT is written in C++, is very large, makes extensive use of object-oriented and multithreaded programming techniques, and contains support for a multitude of commands. The malware was initially discovered in November 2017, but hasn’t been observed in active campaigns until the recent ServHelper campaigns. 

    The malware uses a complicated binary protocol for its C&C and can use a configurable port for communications, yet the observed samples have used port 443. Observed communication includes an initial beacon from the infected system, a key verification message from the system, a key exchange message from the C&C server, and a message containing various system and malware information.

    “Threat actor TA505 is both consistent and prolific. When the group distributes new malware, it may be a blip (like Bart ransomware, which was only distributed for one day in 2016) or like Locky ransomware it may become the dominant strain of malware in the wild,” Proofpoint concludes. 

    Related: Phishing Campaign Delivers FlawedAmmyy, RMS RATs

    Related: Dridex/Locky Operators Unleash New Malware in Recent Attack

    Ionut Arghire is an international correspondent for SecurityWeek.

    Previous Columns by Ionut Arghire:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Tips to bolster cybersecurity, incident response this 4th of July weekend

    July 1, 2022 Cyber Security

    Jon Raper named CISO at Costco

    July 1, 2022 Cyber Security

    2022 RSAC takeaways: Risk management vs compliance

    July 1, 2022 Cyber Security

    3 security lessons we haven’t learned from the Kaseya breach

    July 1, 2022 Cyber Security

    Auston Davis named CISO at Versant Health

    June 30, 2022 Cyber Security

    Lessons learned from slew of recent data breaches

    June 30, 2022 Cyber Security
    Editors Picks

    There’s a better way to bypass Windows 11 install restrictions

    July 2, 2022

    Biden administration floats new oil leasing plan in Gulf of Mexico

    July 1, 2022

    What is the best controller for Xbox consoles?

    July 1, 2022

    Klarna valuation crashes to $6.5bn from $46bn

    July 1, 2022
    Trending Now

    Mexico presses ahead with multibillion-dollar bet on fossil fuels

    By techbizweb

    Sprint’s network has been officially retired

    By techbizweb

    TikTok says it is working to ‘safeguard’ US data and national security

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2022 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.